The Fraud That Targets You, Not Your Customers | HL Hunt

The Fraud That Targets You, Not Your Customers | HL Hunt
Payments & AI

The Fraud That Targets You, Not Your Customers

Most payment fraud advice for small businesses is about customers — stolen cards, chargebacks, disputes. The single largest payment loss most small businesses will ever face runs the other way: paying a genuine invoice to an account somebody else controls. The supplier is real, the work was done, the amount is right, and the only thing wrong is the destination. Every check a business normally performs passes, which is exactly why it works on careful people — and why one specific control, costing a phone call, stops nearly all of it.

By the HL Hunt Research Desk · 15 min read · Updated August 2026

The three shapes it takes

ShapeHow it arrivesWhat's asked
Supplier detail changeA message appearing to come from a supplier you use"Our bank details have changed"
Executive requestA message appearing to come from an owner or senior personAn urgent payment, handled quietly
Fake invoiceAn invoice for something plausiblePayment for goods never supplied

The first is the most costly and the hardest to spot, because everything except the account number is genuine. There's a real supplier, a real relationship, a real invoice for real work, and frequently the correct amount and reference. Some attacks even follow an actual email thread, having obtained access to one side of it.

The second exploits hierarchy — a request from someone the recipient doesn't want to question, with a reason not to check.

The third is the crudest and the easiest to stop with ordinary purchase-order discipline: if nobody ordered it, don't pay it.

Why it works on careful people

The framing that matters, because businesses that suffer these losses are usually not careless.

The attack exploits a legitimate process, not a weakness. Suppliers genuinely do change bank details. Executives genuinely do request occasional urgent payments. The request arrives inside a real relationship, referencing real work.

What the attacker adds is small and decisive:

  • Urgency — a deadline that discourages checking.
  • A reason not to verify — the sender is travelling, in a meeting, hard to reach.
  • A supplied contact — a number or address to confirm with, which the attacker controls.
  • Plausible timing, frequently aligned with a real invoice cycle.

The third item is the whole attack. Everything else is decoration around one requirement: that verification, if it happens at all, happens through a channel the attacker controls.

Which is why this isn't a technical problem and isn't solved by better software. It's a process problem, and it has a process answer.

Everything real but the account
Real supplier, real invoice, real work, correct amount. Every check a business normally runs passes — which is why careful businesses lose this money.

The one control

If a business implements nothing else from this guide, implement this.

Any change to payment details is verified by calling the supplier on a number you already hold — obtained independently of the message requesting the change.

The specifics matter:

  • A number you already have — from a prior invoice, a contract, or your own records. Never a number in the message.
  • A phone call, not a reply. Replying goes to whoever controls the thread.
  • A named person you can identify, not a general line where anyone answers.
  • Before the payment, not after.
  • Every time, with no exceptions for known suppliers or small amounts — because an exception process is what gets exploited.
  • Recorded, with who was called and when.

This defeats the attack entirely. Nearly every payment redirection requires the business to accept new details without confirming through an independent channel. Close that and the attack fails regardless of how convincing it looked.

The reason it isn't universal: it feels rude and it takes five minutes. Which is why it needs to be a stated policy rather than a judgment — a policy is something you can point to, and a judgment is something you can be talked out of.

The supplied contact detail

If a message changing payment details helpfully includes a number to confirm on, that is the strongest available signal that something is wrong. Genuine notifications don't anticipate your verification and pre-supply the channel for it. Use your own records instead, always.

What to notice

Signals worth training people to see:

  • Any change to payment details, in any circumstances — treat this as the trigger regardless of anything else.
  • Urgency attached to a payment, particularly near a weekend or holiday.
  • A request to keep it quiet, or to bypass a normal process.
  • Slight differences in an address or domain, which are easy to miss and easy to check.
  • A change in tone or phrasing from a known contact.
  • A first request from someone you deal with by other means.
  • Pressure applied when someone hesitates — genuine counterparties accept verification.
  • Timing around absences, when the person who'd normally check isn't available.

The most useful single instruction to give staff: urgency and secrecy are not context, they're warning signs. Both exist in the message for one reason, which is to prevent the check that would stop the payment.

Structural controls

Beyond the verification rule, arrangements that limit exposure:

  • Dual authorization above a threshold. A second person breaks the urgency the attack depends on — and per our cash management guide, this belongs on the account that can move money.
  • Separation of setup and approval, so the person adding a payee isn't the one releasing the payment.
  • A limited operating balance, which caps the maximum loss from any single event.
  • Alerts on new payees and large payments, which drive detection speed.
  • A cooling period on new payees before large payments can go to them — simple and effective.
  • Purchase order matching, which stops the fake invoice shape entirely.
  • Daily reconciliation, per our reconciliation guide.
  • Access review after any departure.
  • Multi-factor authentication on email, since compromised email is how the convincing versions start.

The cooling period deserves more use than it gets. A rule that a new payee cannot receive more than a modest amount for several days costs almost nothing and removes the urgency that makes these attacks work — an attacker needs the money moved before anyone checks, and a delay defeats that without requiring anyone to spot anything.

The first hours

Recovery probability falls sharply with time, which makes the response sequence worth knowing before you need it.

  1. Contact your bank immediately and ask them to attempt a recall. Hours matter — funds are frequently moved onward quickly.
  2. Ask them to contact the receiving institution, which may be able to freeze the funds.
  3. Report it to the appropriate authorities, since some maintain mechanisms that can assist with recovery in a narrow window.
  4. Check whether other payments went to the same account or are queued to.
  5. Contact the real supplier, on a known number — they still haven't been paid, and they may be under attack too.
  6. Preserve everything — messages, headers, records. Per our incident guide, don't delete or clean up.
  7. Check whether email was compromised, and change credentials.
  8. Notify your insurer, since coverage typically requires prompt notice.
  9. Review pending payments before releasing anything else.

Step one is the one that determines the outcome. A business that notices within an hour has a materially better chance than one that notices at month-end reconciliation — which is the argument for the alerts in the previous section, expressed as money.

Where the loss lands

The part businesses discover afterward and should understand beforehand.

A payment you authorized is generally treated differently from one you didn't. Card transactions carry the liability framework in our channel analysis, and unauthorized account transactions have their own rules. But a transfer the business itself instructed — even one induced by deception — sits in a different category, and the protections are narrower.

What follows practically:

  • Don't assume the bank will make you whole. The starting position on an authorized payment is frequently that the loss sits with the payer, though outcomes vary and this area continues to develop.
  • Check your insurance specifically. Cyber and crime policies differ substantially on whether they cover payments the business was tricked into making, and this is worth confirming before an incident rather than after.
  • You may still owe the supplier. Paying the wrong account generally doesn't discharge the obligation, so the loss can be the payment plus paying again.
  • Get advice where the amount is significant.

That third point surprises people and is the reason these losses are larger than they first appear. The exposure is roughly twice the invoice, and it's why prevention economics are overwhelming relative to almost any other control a small business could invest in.

The conversation with staff

The attack works by putting someone in a position where checking feels like an accusation. Fix that with policy rather than with vigilance.

What to say explicitly:

  • "The verification policy applies to everyone, including me." The executive-request shape depends on people not questioning the person at the top — and the only thing that reliably defeats it is that person having said, in advance, that they expect to be questioned.
  • "You will never be criticized for delaying a payment to verify it."
  • "Urgency is a reason to check, not a reason to hurry."
  • "If you think you've been caught, say so immediately." Recovery depends on speed, and shame costs hours the business can't afford.
  • "Nobody is expected to spot a convincing fake — the policy is what protects us."

The last is the important one. These attacks are frequently very good, and treating detection as a matter of individual alertness sets people up to fail and to hide it afterward. The process is the defence; the person is not.

Payments you can see, on rails you control

HL Hunt Pay provides card, contactless, and ACH acceptance with payee controls, alerts on new payees and large outbound payments, and reconciliation reporting — so an incorrect payment is visible in hours rather than at month end.

Get Started with HL Hunt Pay

Frequently asked questions

What is payment redirection fraud?

Paying a genuine obligation to an account controlled by someone else, usually after a request appearing to come from a supplier changed the details. Everything except the destination is real.

Why do these attacks work on careful people?

They exploit a legitimate process rather than a weakness. Suppliers do change details, and the attacker only has to ensure verification happens through a channel they control.

Can money sent to a fraudulent account be recovered?

Sometimes, and the odds fall sharply with time — frequently a matter of hours. Detection speed is the single biggest factor, which is why payment alerts matter here more than anywhere.

What is the single most effective control?

Verifying any payment detail change by calling a number you already hold, obtained independently of the request. One call defeats the attack however convincing it looked.

Key takeaways

  • The costliest payment fraud for small businesses is inbound, not customer-side, and everything but the account number is genuine.
  • Verify every payment detail change by phone on a number you already hold — never one supplied in the request.
  • A contact number offered alongside a detail change is the strongest single warning sign available.
  • A cooling period on new payees removes the urgency the attack depends on and requires nobody to spot anything.
  • Act within hours — recall is possible early and rarely later, which is what payment alerts buy you.
  • Paying the wrong account usually doesn't discharge the debt, so the exposure is roughly twice the invoice.

Visibility is what makes recovery possible

Sign up for HL Hunt Pay for acceptance and payment operations with new-payee alerts, threshold controls, and daily reconciliation reporting, so an incorrect payment surfaces while it can still be stopped.

Sign Up for HL Hunt Pay


This guide is educational and does not constitute legal, insurance, or security advice. Liability for authorized payments induced by deception, recovery mechanisms, reporting channels, and insurance coverage vary by jurisdiction, payment method, and policy, and this area continues to develop. Consult qualified counsel and your insurer, and contact your bank immediately if you suspect a payment has been misdirected.